PT-2024-38458 · WordPress · Atarim

Lucio Sá

·

Published

2024-08-10

·

Updated

2024-08-12

·

CVE-2024-7621

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Atarim plugin for WordPress versions prior to 4.0.3
Description The issue allows authenticated attackers with Subscriber-level access and above to modify data due to a missing capability check on the process wpfeedback misc options() function. This can be leveraged to update the plugin's settings and gain access to them.
Recommendations For versions prior to 4.0.3, update to version 4.0.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the process wpfeedback misc options() function to prevent unauthorized modifications.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-7621

Affected Products

Atarim